Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
ReferênciaVexDay Proof
Sorinara Streaming Audio Player 0.9 - '.pla' Local Stack Overflow
CVE-2009-1644localwindows
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via
23RISK
open
Referência
CVE-2016-0199
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISK
open
Referência
CVE-2016-0199
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISK
open
Referência
CVE-2018-8552
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which coul
35RISK
open
Referência
CVE-2017-16887
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
35RISK
open
Referência
CVE-2018-8133
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISK
open
Referência
Microweber 1.2.11 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-0557HIGHwebappsphp
OS Command Injection in microweber/microweber
53RISK
open
Referência
CVE-2020-11022
jQuery has a potential XSS vulnerability
55RISK
open
Referência
CVE-2020-11022
jQuery has a potential XSS vulnerability
55RISK
open
Referência
CVE-2023-50919
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string
75RISK
open
Referência
CVE-2014-9566
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RISK
open
Referência
CVE-2014-9566
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RISK
open
Referência
CVE-2012-3569
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RISK
open
Referência
CVE-2013-2094
CVE-2013-2094HIGHunder attack
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISK
open
ReferênciaVexDay Proof
helplink 0.1.0 - 'show.php' Remote File Inclusion
CVE-2007-5099webappsphp
PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute a
35RISK
open
Referência
CVE-2018-1000811
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages
35RISK
open
Referência
CVE-2015-3093
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
35RISK
open
Referência
CVE-2018-8544
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RISK
open
Referência
CVE-2011-5130
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers t
50RISK
open
ReferênciaVexDay Proof
bSpeak 1.10 - 'forumid' Blind SQL Injection
CVE-2009-1747webappsphp
SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2009-3195
Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to
23RISK
open
Referência
CVE-2009-3196
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arb
23RISK
open
Referência
CVE-2013-2010
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
60RISK
open
Referência
CVE-2009-3203
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2009-3205
SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
Referência
CVE-2015-1487
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RISK
open
Referência
CVE-2016-3316
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a craf
35RISK
open
Referência
CVE-2020-11027
Password reset links invalidation issue in WordPress
38RISK
open
ReferênciaVexDay Proof
jetAudio 7.x - ActiveX 'DownloadFromMusicStore()' Code Execution
CVE-2007-4983remotewindows
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic an
35RISK
open
Referência
CVE-2016-3976
CVE-2016-3976HIGHunder attack
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary fil
83RISK
open
previouspage 531 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.